CVE-2007-0409: Low severity Bea WebLogic Server vulnerability
BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0409?
CVE-2007-0409 has a high severity rating due to the exposure of cleartext passwords to local administrative users.
How do I fix CVE-2007-0409?
To fix CVE-2007-0409, upgrade to a version of Oracle WebLogic Server that does not have this vulnerability, such as any version beyond those specified.
What versions of WebLogic Server are affected by CVE-2007-0409?
CVE-2007-0409 affects BEA WebLogic Server versions 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and the 9.0 initial release.
Who can exploit CVE-2007-0409?
CVE-2007-0409 can be exploited by local administrative users who have access to the system.
What types of data are vulnerable in CVE-2007-0409?
CVE-2007-0409 exposes passwords stored in cleartext within the JDBCDataSourceFactory MBean Properties.